On-chain monitoring says Bitget stolen assets are topped by XRP, ETH, and USDT
Regarding the latest narrative around abnormal asset transfers involving Bitget, current conclusions can only be based on secondary attributions: Odaily Planet Daily, citing Lookonchain monitoring, reports that in the detailed list of stolen assets, the top three by size are XRP, ETH, and USDT. XRP is about 102.93 million units, worth approximately $157.48 million; ETH is about 31,890 units, worth about $85.75 million; USDT is about 34.75 million units, worth about $34.75 million. The list also includes USDC at about 21.05 million units, USD₮0 at about 19.67 million, XAUt at about 3,000 units worth $12.82 million, BNB at about 12,719 units worth $9.88 million, AVAX at about 821,012 units worth $8.38 million, and TRX at about 20.59 million units worth about $7.07 million.
It is important to emphasize that these figures are estimates from on-chain monitoring institutions and have been relayed by the media. The evidence does not include Bitget’s official announcements, explanations of the attack path, or updates on freezing or fund recovery, and it cannot directly prove a final loss figure under any specific accounting standard.
The background of the incident is that once a centralized exchange is involved in large-scale abnormal movement across multiple assets, the market will first distinguish between “hot-wallet operational reallocation,” “security incidents,” and “on-chain label misclassification.” This material only provides an asset-composition snapshot, presenting a mixture of stablecoins, mainstream chain assets, and platform-related holdings. If the monitoring attribution holds, the affected liquidity is not limited to a single chain or a single trading pair.
At the core factual level, only three points can be confirmed: the attribution of the message is that Odaily relays Lookonchain; the listed top items are highly concentrated, with the XRP single-line estimate already exceeding $150 million; and the remaining assets are relatively scattered, ranging from several million to just over tens of millions of dollars. Beyond that, with insufficient information, no conclusion can be drawn about the attacker’s identity, the intrusion method, whether private keys or a permissions system were involved, or whether user assets are fully covered.
In terms of logical breakdown, the first question is the accounting scope: labeling an on-chain address as “stolen” does not necessarily equal the exchange’s final net loss. If later events include freezing, returns, insurance payouts, or internal reserves absorbing the impact, the transfer size visible to outsiders would differ from the true economic impact.
The second question is the structure: stablecoins and assets like ETH and BNB are easier to move across venues quickly, while XRP and TRX depend on their respective networks and the exchange’s deposit/withdrawal channels, making tracking and interception more difficult in different ways.
The third question is timing: in the absence of an official timeline, any claim that directly infers a systemic solvency crisis from the asset details crosses the boundary of available evidence.
The impact path on the crypto market is more likely to be reflected in sentiment and risk control, rather than instantly changing the fundamentals. In the short term, trading platforms will re-verify deposits/withdrawals, address labels, and abnormal alerts. Market makers may reduce exposure to related counterparty platforms, while on-chain analysts will continue tracking whether funds enter mixers, cross-chain bridges, or over-the-counter exchange channels. If stablecoins make up a high proportion, market attention will focus on the issuer’s freezing capability and legal cooperation. If the share of mainstream coins rises, attention will shift to whether selling pressure is concentrated in a small number of liquidity pools. What must be avoided is equating “monitoring-detected transfers” directly with “already sold off.”
Editor’s note: This is a security lead worth continuing to track, but the strength of current evidence only supports “on-chain monitoring details relayed by the media,” and does not support confirming the root cause of the incident, the responsible party, or the final shortfall. Readers should focus on three things going forward: whether Bitget releases verifiable official announcements; whether the relevant stablecoin and exchange addresses show signs of freezing or fund return; and whether law-enforcement and audit institutions provide an independent set of figures. Until official confirmation, all amounts should be treated as estimated ranges rather than definitive conclusions.
#加密新闻 #BTC #ETH #BNB
Regarding the latest narrative around abnormal asset transfers involving Bitget, current conclusions can only be based on secondary attributions: Odaily Planet Daily, citing Lookonchain monitoring, reports that in the detailed list of stolen assets, the top three by size are XRP, ETH, and USDT. XRP is about 102.93 million units, worth approximately $157.48 million; ETH is about 31,890 units, worth about $85.75 million; USDT is about 34.75 million units, worth about $34.75 million. The list also includes USDC at about 21.05 million units, USD₮0 at about 19.67 million, XAUt at about 3,000 units worth $12.82 million, BNB at about 12,719 units worth $9.88 million, AVAX at about 821,012 units worth $8.38 million, and TRX at about 20.59 million units worth about $7.07 million.
It is important to emphasize that these figures are estimates from on-chain monitoring institutions and have been relayed by the media. The evidence does not include Bitget’s official announcements, explanations of the attack path, or updates on freezing or fund recovery, and it cannot directly prove a final loss figure under any specific accounting standard.
The background of the incident is that once a centralized exchange is involved in large-scale abnormal movement across multiple assets, the market will first distinguish between “hot-wallet operational reallocation,” “security incidents,” and “on-chain label misclassification.” This material only provides an asset-composition snapshot, presenting a mixture of stablecoins, mainstream chain assets, and platform-related holdings. If the monitoring attribution holds, the affected liquidity is not limited to a single chain or a single trading pair.
At the core factual level, only three points can be confirmed: the attribution of the message is that Odaily relays Lookonchain; the listed top items are highly concentrated, with the XRP single-line estimate already exceeding $150 million; and the remaining assets are relatively scattered, ranging from several million to just over tens of millions of dollars. Beyond that, with insufficient information, no conclusion can be drawn about the attacker’s identity, the intrusion method, whether private keys or a permissions system were involved, or whether user assets are fully covered.
In terms of logical breakdown, the first question is the accounting scope: labeling an on-chain address as “stolen” does not necessarily equal the exchange’s final net loss. If later events include freezing, returns, insurance payouts, or internal reserves absorbing the impact, the transfer size visible to outsiders would differ from the true economic impact.
The second question is the structure: stablecoins and assets like ETH and BNB are easier to move across venues quickly, while XRP and TRX depend on their respective networks and the exchange’s deposit/withdrawal channels, making tracking and interception more difficult in different ways.
The third question is timing: in the absence of an official timeline, any claim that directly infers a systemic solvency crisis from the asset details crosses the boundary of available evidence.
The impact path on the crypto market is more likely to be reflected in sentiment and risk control, rather than instantly changing the fundamentals. In the short term, trading platforms will re-verify deposits/withdrawals, address labels, and abnormal alerts. Market makers may reduce exposure to related counterparty platforms, while on-chain analysts will continue tracking whether funds enter mixers, cross-chain bridges, or over-the-counter exchange channels. If stablecoins make up a high proportion, market attention will focus on the issuer’s freezing capability and legal cooperation. If the share of mainstream coins rises, attention will shift to whether selling pressure is concentrated in a small number of liquidity pools. What must be avoided is equating “monitoring-detected transfers” directly with “already sold off.”
Editor’s note: This is a security lead worth continuing to track, but the strength of current evidence only supports “on-chain monitoring details relayed by the media,” and does not support confirming the root cause of the incident, the responsible party, or the final shortfall. Readers should focus on three things going forward: whether Bitget releases verifiable official announcements; whether the relevant stablecoin and exchange addresses show signs of freezing or fund return; and whether law-enforcement and audit institutions provide an independent set of figures. Until official confirmation, all amounts should be treated as estimated ranges rather than definitive conclusions.
#加密新闻 #BTC #ETH #BNB
